Earlier quoted context omitted.
Why not? This is highly specialized research that not even well-paid Google employees were able to do. This is actually quite common in recent years for bug hunters and exploit developers. I can think of a dozen or so companies that do the same thing. Immunity is another example. Trying to use a moral argument to get out of compensating someone when you have the resources to do so is shameful. Sorry, but this stuff i…
"They can either pay a nominal fee for doing their security work for them, or they can hire some equally talented people and fund this type of research on their own internally." What makes you think they don't already? You make it sound like Google doesn't give a shit about security. That clearly isn't the case.
That doesn't mean they're going to find everything, though.
At the end of the day, private companies are perfectly within their rights to do offensive research against Google products, to be selective about how they disclose their results, and to tell the public whatever they want about those results. As long as they aren't lying, there's nothing unethical about it.